CVE-2021-3825
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)
Description
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Affected (1)
Products: Pardus: Liderahenk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.1.15 |
References (5)
Source: iletisim@usom.gov.tr
ExploitThird Party Advisory
Source: iletisim@usom.gov.tr
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.